CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

174 vulnerabilities with CWE-359
CVE-2024-13953 MEDIUM
ASPECT-Enterprise <3.* - Info Disclosure
CVSS 4.9
CVE-2024-42325 LOW
Zabbix - Info Disclosure
CVSS 3.5
CVE-2024-10267 HIGH
transformeroptimus/superagi - Info Disclosure
CVSS 7.5
CVE-2024-13228 MEDIUM
Qubely - Advanced Gutenberg Blocks <1.8.13 - Info Disclosure
CVSS 4.3
CVE-2024-11216 HIGH
PozitifIK Pik Online <3.1.5 - Privilege Escalation
CVSS 7.6
CVE-2024-13217 MEDIUM
Jeg Elementor Kit <2.6.11 - Info Disclosure
CVSS 4.3
CVE-2024-12041 MEDIUM
Directorist: AI-Powered WordPress Business Directory Plugin - Info ...
CVSS 5.3
CVE-2024-13216 MEDIUM
HT Event - WordPress Event Manager Plugin for Elementor <1.4.7 - In...
CVSS 4.3
CVE-2024-13215 MEDIUM
Elementor Addon Elements <1.13.10 - Info Disclosure
CVSS 4.3
CVE-2024-11396 MEDIUM
Event Monster - Info Disclosure
CVSS 5.3
CVE-2024-41780 MEDIUM
IBM Jazz Foundation <7.1.0 - Info Disclosure
CVSS 4.2
CVE-2024-49765 MEDIUM
Discourse - Auth Bypass
CVSS 5.3
CVE-2024-11712 MEDIUM
WP Job Portal - Info Disclosure
CVSS 5.3
CVE-2024-42494 MEDIUM
Ruijie Reyee OS <2.320 - Info Disclosure
CVSS 6.5
CVE-2024-53258 MEDIUM
Autolab < 3.0.2 - Missing Authorization
CVSS 5.3
CVE-2024-49025 MEDIUM
Microsoft Edge Chromium < 131.0.2903.48 - Information Disclosure
CVSS 5.4
CVE-2024-11206 HIGH
com.transsion.phoenix - Info Disclosure
CVSS 7.5
CVE-2024-49386 MEDIUM
Acronis Cyber Files <9.0.0x24 - Info Disclosure
CVSS 5.7
CVE-2024-47087 MEDIUM
Apex Softcell LD Geo - Info Disclosure
CVSS 6.5
CVE-2024-47085 MEDIUM
Apex Softcell LD DP Back Office - Info Disclosure
CVSS 6.5
CVE-2024-46979 MEDIUM
Xwiki < 14.10.21 - Information Disclosure
CVSS 5.3
CVE-2024-8891 MEDIUM
CIRCUTOR Q-SMT <1.0.4 - Info Disclosure
CVSS 5.3
CVE-2024-45787 MEDIUM
Reedos Aim-star - Denial of Service
CVSS 6.5
CVE-2024-45591 MEDIUM
Xwiki < 15.10.9 - Missing Authorization
CVSS 5.3
CVE-2024-44113 MEDIUM
SAP Business Warehouse - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 174